Version 6.9.1 Vulnerability Fixes - Question | JoomShaper

is live, now with multi-currency selling.

Version 6.9.1 Vulnerability Fixes

MiBa

MiBa

SP Page Builder 6 days ago

From the description it is not clear which versions are affected by these vulnerabilities. Could you please clarify?

Fixed an authorized SQL injection vulnerability in article and module save operations caused by insufficient input validation of database identifiers. [CVE-2026-78375]

Fixed a CAPTCHA bypass vulnerability in the Opt-in Form addon by validating CAPTCHA parameters against the configured addon settings instead of request-supplied values. [CVE-2026-79700]

Fixed a CAPTCHA bypass vulnerability in the Contact Form, Opt-in Form and Form Builder addons when placed inside a module, ensuring the CAPTCHA plugin's verification result is always enforced. [CVE-2026-79701]

Fixed an authorization issue in the Media Manager that allowed users with editing permissions to rename files outside the intended media directories. [CVE-2026-81564]

Fixed a permission issue when creating or updating menu items through SP Page Builder, ensuring the required Joomla menu permissions are properly enforced. [CVE-2026-81565]

Fixed an issue in the Media Manager that allowed users with author-level permissions to upload files to unintended directories within the site. [CVE-2026-81566]

0
8 Answers
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 6 days ago #233640

Hi MiBa,

Thanks for asking — here are the affected version ranges for each item. All six are fixed in SP Page Builder 6.9.1, so any site running 6.9.0 or earlier within the ranges below should update.

CVE Issue Affected versions
CVE-2026-78375 SQL injection in article/module save operations 5.2.1 – 6.9.0 (Free & Pro)
CVE-2026-79700 CAPTCHA bypass in the Opt-in Form addon 5.1.4 – 6.9.0 (Pro)
CVE-2026-79701 CAPTCHA bypass in Contact Form, Opt-in Form and Form Builder inside a module 3.2.6 – 6.9.0 (Pro)
CVE-2026-81564 Media Manager rename outside the intended media directories 4.0.0 – 6.9.0 (Free & Pro)
CVE-2026-81565 Media Manager upload to unintended directories 4.0.0 – 6.9.0 (Free & Pro)
CVE-2026-81566 Missing Joomla menu permission check when creating/updating menu items 4.0.0 – 6.9.0 (Free & Pro)

A few notes that may help you judge the risk on your own site:

  • CVE-2026-79700 and CVE-2026-79701 need no login — they only apply if you have Contact Form, Opt-in Form or Form Builder published with CAPTCHA enabled.
  • The remaining four require an authenticated account with elevated permissions (author-level or above, depending on the issue), so they are mainly a concern on sites with multiple back-end users.

Updating to 6.9.1 addresses all of these. Let us know if you run into anything after updating.

Best regards,

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 4 days ago #233827

Thanks for accepting the answer:)

Have a nice day!

0
D
deevau
Accepted Answer
6 days ago #233642

And why users did not recieve a E-Mail notification about this security update?

0
SC
Stuart Clark
Accepted Answer
6 days ago #233653

I have NEVER received an update notification email from Joomshaper!

0
WJ
Wilson Junior
Accepted Answer
5 days ago #233657

I didn't receive any notification about 6.9.1 either. If we lose trust in SP PageBuilder, it will be difficult to even keep Joomla as our CMS of choice.

0
Mo Ahmed
Mo Ahmed
Accepted Answer
6 days ago #233651

This is really bad management for security releases.

I mentioned this for the last release. Now I need to take emergency time out to patch all my sites and ensure nothing is broken.

I only found out by chance by logging into my control panel a few minutes ago.

0
K
Kieron
Accepted Answer
5 days ago #233659

Joomshaper, You really need to do better. I understand that software 'holes' exist in code written by humans but your communication is VERY poor. You need to do better. The only emails I ever get are invoices!

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 5 days ago #233747

Hi all,

You're right to raise this, and I'm sorry. The notification email for 6.9.1 did go out, but it went out later than the release itself — so for a window there was no way to hear about it unless you happened to log into your control panel or watch the changelog. For a security release that's backwards: the notice should reach you when the update does, not after. That's on us.

@Mo Ahmed — you flagged this on the previous release too, which makes it worse, not better. Noted, and I'm carrying it forward rather than letting it sit in the thread.

@Stuart Clark, @Wilson Junior — if you've never received a release email from us, that points to something at the account or delivery level rather than just this one send. Sent a email to [email protected] with your account email and we will check whether it's on the notification list and whether our messages to it are bouncing or being filtered.

In the meantime, updating to 6.9.1 closes all six issues listed above — that's the immediate action; everything else is process on our side.

On the broader point, I'm not going to argue with it. "It was in the changelog" isn't a substitute for telling you directly. I'm taking this thread to the team with the specific ask that security notifications go out alongside the release.

Best regards,

0